Two high-severity vulnerabilities were disclosed in rust-openssl, the Rust bindings for OpenSSL, affecting multiple 0.9.x and 0.10.x releases prior to 0.10.78. CVE-2026-41898 affects versions from 0.9.24 up to, but not including, 0.10.78, where several FFI trampoline callback paths passed a closure-returned usize to OpenSSL without validating it against the output buffer size. The flaw can trigger buffer overflows and leak adjacent memory to a network peer, and it is mapped to CWE-126 and CWE-130.
A second issue, CVE-2026-41681, affects versions from 0.10.39 up to, but not including, 0.10.78, in MdCtxRef::digest_final(), which writes EVP_MD_CTX_size(ctx) bytes to the caller buffer without checking whether the buffer is large enough. The resulting out-of-bounds write can cause stack corruption and is reachable from safe Rust, with the weakness classified as CWE-121. Both vulnerabilities were addressed in rust-openssl 0.10.78, with public advisories, code references, and fix details released alongside the CVE records.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-41898 was published for rust-openssl, affecting versions 0.9.24 through before 0.10.78. The issue stems from FFI trampoline callback paths forwarding a closure-returned length to OpenSSL without validating it against the output buffer, potentially leaking adjacent memory or causing overflow-related behavior.
CVE-2026-41681 was published for rust-openssl, affecting versions 0.10.39 through before 0.10.78. The flaw allows MdCtxRef::digest_final() to write past a caller-provided buffer because no length check is performed before EVP_DigestFinal() writes the digest output.
rust-openssl version 0.10.78 was released with fixes for two vulnerabilities: unchecked callback-returned lengths in PSK and cookie trampolines, and a missing output-length check in MdCtxRef::digest_final(). The fixes addressed affected version ranges below 0.10.78 referenced by later advisories.
The rust-openssl project released openssl-v0.10.78 on 2026-04-19 to address five security vulnerabilities disclosed via GitHub Security Advisories. The fixes covered multiple memory-safety issues, including key derivation, PEM password callback handling, AES key unwrap bounds checking, digest finalization, and unchecked callback-returned lengths in PSK and cookie trampolines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.